CVE-2023-3306 is a critical improper access controls vulnerability affecting the Ruijie RG-EW1200G EW_3.0(1)B11P204 firmware, specifically within the Admin Password Handler component. This flaw allows for remote, unauthenticated attackers to gain full control over the device, leading to complete compromise of confidentiality, integrity, and availability. While no active exploitation has been confirmed, public exploit details are available, and the vendor has not responded to disclosure attempts. Despite its high severity and public exploit, there is currently minimal community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
ew_3.0\(1\)b11p204CPE matchmatch criteria | cpe:2.3:o:ruijie:rg-ew1200g_firmware:ew_3.0\(1\)b11p204:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.